Interestingly NIST are also saying SMS for two-factor auth is also out.
SMS is a funny one. In theory, like email, it's insecure. In practice, short of a targeted attack it's safe. I assume nobody wants access that urgently to my spamtrap email account so that it's safe.